CVE-2024-31408: Aiphone Co., Ltd Ix-BA
High severity, CVSS 8.0. EPSS: 1.1% chance of exploitation in the next 30 days.
OS command injection vulnerability exists in AIPHONE IX SYSTEM and IXG SYSTEM. A network-adjacent authenticated attacker may execute an arbitrary OS command with root privileges by sending a specially crafted request.
Affected products
- Aiphone Co., Ltd Ix-BA: up to and including 7.10
- Aiphone Co., Ltd Ix-Bau: up to and including 7.10
- Aiphone Co., Ltd Ix-Bb: up to and including 7.10
- Aiphone Co., Ltd Ix-Bbt: up to and including 7.10
- Aiphone Co., Ltd Ix-Bu: up to and including 7.11
- Aiphone Co., Ltd Ix-Da: up to and including 7.10
- Aiphone Co., Ltd Ix-Dau: up to and including 7.10
- Aiphone Co., Ltd Ix-DB: up to and including 7.10
- Aiphone Co., Ltd Ix-Dbt: up to and including 7.10
- Aiphone Co., Ltd Ix-Du: up to and including 7.11
- Aiphone Co., Ltd Ix-Dv: up to and including 7.11
- Aiphone Co., Ltd Ix-Dvf: up to and including 7.11
- Aiphone Co., Ltd Ix-Dvf-2ra: up to and including 7.11
- Aiphone Co., Ltd Ix-Dvf-L: up to and including 7.11
- Aiphone Co., Ltd Ix-Dvf-P: up to and including 7.11
- Aiphone Co., Ltd Ix-Dvf-Ra: up to and including 7.11
- Aiphone Co., Ltd Ix-Dvm: up to and including 7.10
- Aiphone Co., Ltd Ix-Dvt: up to and including 7.11
- Aiphone Co., Ltd Ix-Ea: up to and including 7.10
- Aiphone Co., Ltd Ix-Eat: up to and including 7.10
- Aiphone Co., Ltd Ix-Eau: up to and including 7.10
- Aiphone Co., Ltd Ix-Fa: up to and including 7.10
- Aiphone Co., Ltd Ix-Mv: up to and including 7.10
- Aiphone Co., Ltd Ix-MV7-B: up to and including 7.10
- Aiphone Co., Ltd Ix-MV7-Bt: up to and including 7.10
- and 29 more
Published 2024-11-22. Last modified 2026-06-17.